Illicit loaders spread by malware trio via DLL search order hijacking Telecommunications and manufacturing organizations across Central and South Asia have been targeted by a new attack campaign spreading the RainyDay and Turian backdoors, as well as a novel PlugX malware variant, which leverages DLL search order hijacking to run illicit loaders, Cyber Security News reports.
Newly emergent YiBackdoor malware was discovered to have source code significantly similar to the Latrodectus and IcedID payloads, according to The Hacker News.
The research by Check Point Research highlights how Nimbus Manticore, also known as MuddyWater, employs sophisticated malware to infiltrate the networks of European companies.